Hiring.Camp

Director, Cyber Defense

Click Here to Learn More

·

Today

Salary
$130k – $242k
Location
United States, United States of America
Type
Full-time
Seniority
Director
Education
Bachelor
Source
Workday

Description

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

We're looking for a Director, Cyber Defense to lead the teams that keep our travelers, colleagues, and data safe: Cyber Security Incident Response (CSIRT), Cyber Threat Intelligence (CTI), Detection Engineering, and Data Security Investigations (DSI). This is a hands-on leadership role for someone who has run security operations at scale, knows what good incident command looks like under pressure, and can build detection and intelligence programs that get ahead of threats rather than just reacting to them.

You'll set the strategy for how we detect, investigate, and respond to security incidents and data-handling concerns across a global business. You'll also be a key partner to Legal, Privacy, HR, and executive leadership when incidents touch sensitive data or people. Amex GBT operates in a sector where trust is the product — this role protects that trust.

What You'll Do

Team leadership and strategy

  • Lead and grow four connected teams — CSIRT, CTI, Detection Engineering, and DSI — as one cyber defense function with shared priorities and a common operating rhythm
  • Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership
  • Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high-pressure incidents
  • Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage
  • Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders

Incident response (CSIRT)

  • Own the incident response program end to end: playbooks, severity classification, escalation paths, and after-action reviews
  • Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives
  • Run regular tabletop exercises and simulations to test readiness across the company, not just within security
  • Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it

Cyber threat intelligence (CTI)

  • Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers
  • Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities
  • Represent us in relevant intelligence-sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility
  • Deliver clear, decision-useful threat briefings to technical teams and to executive leadership

Detection engineering

  • Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior (MITRE ATT&CK and similar frameworks)
  • Drive continuous tuning to cut down false positives while closing coverage gaps
  • Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage
  • Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection

Data Security Investigations (DSI)

  • Lead investigations into potential inappropriate access, use, or disclosure of sensitive data — including privacy cases involving colleagues, contractors, or third parties
  • Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings
  • Work closely with Legal, Privacy, and HR on cases that may carry disciplinary, regulatory, or legal exposure, and know when and how to loop them in
  • Advise on data loss prevention, access controls, and insider risk indicators based on investigation trends
  • Handle every case with the discretion and judgment these situations require, balancing thoroughness with fairness to everyone involved

What We're Looking For

  • 10+ years in cybersecurity, including 5+ years leading incident response, security operations, or a similar function
  • Direct experience running or overseeing sensitive investigations involving data privacy, insider risk, or employee conduct, ideally in partnership with Legal or HR
  • Working knowledge of threat intelligence practices and how intelligence should shape detection priorities
  • Experience with detection engineering concepts: SIEM/EDR content development, use case design, and frameworks like MITRE ATT&CK
  • A track record of leading through live incidents, including clear communication to non-technical executives under pressure
  • Familiarity with privacy and data protection regulations relevant to a global business (for example, GDPR, CCPA, and similar frameworks)
  • Experience managing managers and building teams, not just individual contributors
  • A bachelor's degree in a related field, or equivalent experience

Preferred

  • Experience in travel, hospitality, financial services, or another sector handling large volumes of personal and payment data
  • Relevant certifications such as CISSP, GCIH, GCFA, GCTI, or equivalent
  • Experience with 24/7 or global follow-the-sun security operations models
  • Background working with outside counsel, forensics vendors, or law enforcement on significant incidents

     

Location

United States

     

The US national base salary range for this position is from 

$130,200.00 - $241,800.00

The national range provided includes the base salary that Amex GBT expects to pay for the role.  Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.

In addition to base salary, the anticipated range of which is posted above, this role is eligible for a discretionary annual bonus, which rewards participants based on company and individual performance.

For information about our comprehensive US benefits programs and eligibility, please review our Benefits-at-a-Glance document.

Benefits at a glance

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Click Here for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;" please apply anyway. You may be exactly the person we’re looking for!

Skills

CybersecuritySIEMLoss PreventionGDPRCISSP

Similar Jobs

7

Director, Cyber Defense

Professional Kyndryl · No City (KGB51624) London, United Kingdom · Remote

3 weeks ago

Director, Cyber Defense Principal Engineer

Alnylam Pharmaceuticals · US +1 · Remote

2 months ago

Consulting Director - Cyber Defense

Pwc · Singapore - Marina One

5 months ago

Senior Director of Cyber Defense Architecture & Engineering

AmerisourceBergen is now Cencora! Explore our careers. · USA > TX > Remote, United States of America +4 · Remote

3 weeks ago

Director of Cyber Defense

Northmark · Dallas - MacArthur Blvd, United States of America

4 weeks ago

Cyber Defense, Adversary Emulation Director

Mizuho Mizuho is in growth · MetroPark, United States of America

1 month ago

Global Director of Autonomous Cyber Defense and Security Event Triage (SOC)

Mufgub · Watermark - 410 North Scottsdale Road, United States of America +1

1 month ago